Executive brief
LobeHub, an AI agent collaboration platform, contained a security flaw in its web proxy component. An attacker could use this flaw to make the LobeHub servers send unauthorized requests to other websites or internal systems. This could lead to the exposure of internal infrastructure details or the injection of malicious cookies into a user's browser, potentially allowing an attacker to hijack user sessions.
Technical details
An unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in LobeHub's `/webapi/proxy` endpoint. The root cause is a missing `checkAuth()` wrapper in the route handler located at `src/app/(backend)/webapi/proxy/route.ts`, which allows the endpoint to accept and fetch any URL provided in a POST body without authentication. Beyond standard SSRF, the proxy reflects upstream `Set-Cookie` headers, enabling attackers to perform cookie injection on the `lobehub.com` domain. This can be leveraged for session fixation attacks against Clerk-managed sessions or to leak Vercel deployment metadata (e.g., `X-Vercel-Id` headers). The vulnerability is resolved in version 2.1.57 by implementing proper authentication checks.
Affected products
- LobeHub LobeHub < 2.1.57
Timeline
- 2026-06-03: advisory: Initial GitHub security advisory published
- 2026-06-23: disclosed: CVE-2026-54157 published to NVD
- 2026-06-23: patched: Fix released in version 2.1.57